Skip to main content
Back to BlogAnalyse IA

How to prove that content was AI-generated, and what it means for your SMB

October 3, 2026

How to prove that content was AI-generated, and what it means for your SMB

As of September 1, 2026, supported image, video, and audio formats produced by Claude carry a verifiable provenance signature, and text carries a watermark. For a Quebec SMB, the question is no longer "can anyone tell?" but "what do we do with this in our day-to-day operations?"

The short answer: yes, it is now possible to trace a file produced by an AI back to its origin. Anthropic announced on September 1, 2026 that supported image, video, and audio formats generated by Claude through the code execution tool carry Content Credentials to the C2PA standard when retrieved via the Files API, and that text produced by Claude Fable 5.1 and Claude Mythos 5.1 carries a text watermark. No changes are required on the application side: the marking is automatic. What this does not do: it does not create a legal obligation to label your content, and it does not replace an internal AI usage policy.

What is a "Content Credential" C2PA, in practical terms?

It is an identity card attached to the file itself. The standard comes from the Coalition for Content Provenance and Authenticity (C2PA), a project of the Joint Development Foundation, an American 501(c)(6) nonprofit that develops open technical standards for content provenance (source: c2pa.org). The coalition was founded in February 2021 by Adobe, Arm, BBC, Intel, Microsoft, and Truepic; its specification is currently at version 2.4 [publication date to be confirmed: the spec page does not display it]. Worth noting: it is the subject of an international standardization project (ISO/CD 22144, "Authenticity of information", still under development), so it is not yet a published ISO standard. The principle: instead of guessing after the fact whether an image was generated, you read the declared provenance directly from the file.

For an SMB, the value is not theoretical. It touches three very ordinary situations:

  • A visual produced by a supplier: knowing what was generated versus what was photographed.
  • A document received by email in a sensitive file (claim, incident, HR matter).
  • Your own marketing content: being able to demonstrate your process if a client asks.

Be aware of the limitation: a file without a Content Credential is not proof that it is authentic, and provenance information can be lost when a file is recompressed or passes through a platform that does not preserve it. It is one more data point, not a verdict.

Does Law 25 require me to identify content produced by AI?

No. And it is important to say this clearly, because the confusion is widespread.

The Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), amended by Law 25, governs personal information, not content provenance. The closest obligation is found in section 12.1: when a decision is based exclusively on automated processing, the organization must inform the person concerned and, upon request, explain the information used and the main factors that led to the decision. Meaningful human involvement in the process changes the picture.

In other words: the real compliance question is not "was this text written by an AI?" but "is an AI making a decision about a person, on its own?" That is where the obligation lies.

C2PA marking is still useful for compliance in a broader sense: it documents your processes. An organization that can show how content was produced and who reviewed it is an organization that inspires confidence in a client, an insurer, or a regulator.

The question nobody asks before choosing a model: where does the data go?

This is the part of the September 1 announcement nobody is talking about, and yet it is the part with the greatest impact on a Quebec SMB.

In the same release notes, Anthropic clarifies that Claude Fable 5.1 and Claude Mythos 5.1 require a 30-day data retention period and are not available in zero data retention mode without express authorization from Anthropic.

Choosing a model is a governance decision, not just a performance decision. A more powerful model may be incompatible with the confidentiality commitments you have made to your clients or with your personal information handling policy. This does not mean ruling it out, but evaluating the implications up front and formally documenting the decision.

This is exactly the kind of trade-off that the CAPE methodology (Conceive · Activate · Propel · Evolve) places at the Conceive stage: you set the framework before you plug in the tool, not the other way around.

Four concrete steps for an SMB, this quarter

  1. Take stock of your actual AI usage. Not the official usage: the real usage, the kind happening across your teams. You will almost always find more than expected.
  2. Write a one-page usage rule. What can be submitted to an AI tool, what cannot, and who reviews before publication.
  3. Check the data retention policy of the model or models you use and record the answer in your register. The default configuration is not always what you think it is.
  4. Keep a named human reviewer on all content and all decisions that affect a person. It is the best safeguard, and it is also what keeps you out of the scope of section 12.1.

FAQ

Can I reliably detect AI-generated text? No, not in general. The watermark announced on September 1, 2026 applies to text produced by Claude Fable 5.1 and Claude Mythos 5.1: it is a vendor-specific mechanism, not a universal detector. Generic "AI detector" tools produce false positives.

Is a file without a Content Credential suspicious? No. The absence of provenance proves nothing: the vast majority of files in circulation carry none, and the information can be lost during processing.

Does Law 25 require me to disclose that I use AI? Not as such. The obligation under section 12.1 targets decisions based exclusively on automated processing concerning a person. A marketing communication drafted with AI assistance and reviewed by a human is not covered by that section.

Is it worth waiting for the regulatory landscape to clarify? The steps recommended above (inventory, usage rule, human review) have value regardless of how regulation evolves. They are low-cost and they reduce risk right now.


You are already using AI in your organization and want to know where you stand on framework and compliance? Write to us: we start from your actual usage, not a theoretical questionnaire.

LinkedIn Version

Do you know which AI tools your teams are actually using, and where the data they enter into them goes?

On September 1, Anthropic announced two things in the same release notes. The first made the rounds online: supported image, video, and audio formats produced by Claude now carry a provenance signature to the C2PA standard, and text carries a watermark.

The second flew under the radar, and it is the one that matters for an SMB: these new models require a 30-day data retention period and are not available in zero retention mode without express authorization.

Choosing an AI model is therefore not just a performance decision. It is a governance decision.

And no, Law 25 does not require you to label content produced by AI. Its section 12.1 targets something else: decisions based exclusively on automated processing concerning a person. The real question is not "who wrote this text" but "is a machine making a decision about someone, on its own?"

Three steps worth their weight in gold, regardless of where regulation ends up: take stock of your actual usage, write a one-page rule, keep a named human reviewer.

AI Law25 QuebecSMB DataGovernance DigitalTransformation

Sources cited

  • Anthropic, Claude Platform release notes, September 1, 2026 entry (text watermark, C2PA Content Credentials on image/video/audio via the Files API; 30-day data retention requirement for Claude Fable 5.1 and Claude Mythos 5.1): https://platform.claude.com/docs/en/release-notes/api, accessed 2026-09-03. (The former address docs.anthropic.com/en/release-notes/api redirects here: cite the canonical address.)
  • Coalition for Content Provenance and Authenticity (C2PA), About (project of the Joint Development Foundation, 501(c)(6) nonprofit, open technical standards for content provenance): https://c2pa.org/about/, accessed 2026-09-03.
  • C2PA, C2PA Specification, version 2.4 [publication date to be confirmed: the spec page does not display it]: https://spec.c2pa.org/specifications/specifications/2.4/index.html, accessed 2026-09-03.
  • ISO, ISO/CD 22144, Authenticity of information: project under development at ISO/TC 171/SC 2, not published as of the date of consultation, verified 2026-09-03.
  • Act respecting the protection of personal information in the private sector, CQLR c. P-39.1, s. 12.1 (decision based exclusively on automated processing): primary legislative reference, text to be appended at time of publication.